Secret scanning validity checks now included in the alert timeline
Summary
Validity checks for secret scanning alerts have now been included in the alert timeline, improving historical context.
GitHub secret scanning lets you know if your secret is active
or inactive
with partner validity checks. These checks are run on an ongoing basis for supported providers for any repositories that have enabled the validity check feature.
Starting today, secret validity will now be reflected in an alert’s timeline, alongside the existing resolution and bypass events. Changes to a secret’s validity will continue to be included in an organization’s audit log.
Sign up for a 60 minute feedback session on secret scanning and be compensated for your time.
Learn how to secure your repositories with secret scanning or become a secret scanning partner.